Bonjours, merci pour tes conseils,
j'ai fais la manip avec combofix,
à priori avec succès(je joint ici
le rapport). Ce qui m'ennui c'est
que lorsque je lance antivir il
n'apparait pas dans la barre de
tache en bas à droite...je vais redémarrer
pour voir si cela change.
Ensuite je refais un rapport
Hijack puis je lance un scan antivir
en suivant tes conseils.
ComboFix 09-01-19.05 - remi 2009-01-20 14:44:45.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1475 [GMT 2:00]
Lancé depuis: c:\users\remi\Desktop\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\resycled
c:\resycled\boot.com
c:\windows\system32\drivers\msqpdxxplbbrkp.sys
c:\windows\system32\hpowiax8.dll
c:\windows\system32\msqpdxonxvjnyb.dll
c:\windows\system32\tmp.reg
D:\Autorun.inf
D:\resycled
d:\resycled\boot.com
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MSQPDXSERV.SYS
-------\Service_MSQPDXSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-20 au 2009-01-20 ))))))))))))))))))))))))))))))))))))
.
2009-01-20 11:49 . 2009-01-20 11:49 <REP> d-------- c:\users\All Users\NortonInstaller
2009-01-20 11:49 . 2009-01-20 11:49 <REP> d-------- c:\programdata\NortonInstaller
2009-01-19 22:01 . 2009-01-19 22:01 <REP> d-------- c:\program files\Trend Micro
2009-01-19 21:42 . 2009-01-19 21:42 <REP> d-------- C:\hijack
2009-01-18 18:30 . 2009-01-18 18:30 <REP> d-------- c:\program files\UsbFix
2009-01-13 16:54 . 2009-01-13 17:00 <REP> d-------- c:\users\All Users\Spybot - Search & Destroy
2009-01-13 16:54 . 2009-01-13 17:00 <REP> d-------- c:\programdata\Spybot - Search & Destroy
2009-01-13 16:54 . 2009-01-13 16:54 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-01-11 15:31 . 2009-01-11 15:31 0 --a------ C:\ARK8F51.tmp
...le corps du message étant très long, il fait bugger firefox...si il est necessaire je peux essayer de l'envoer
en plusieurs morceaux...
+ 2008-01-05 11:22:01 14,848 ----a-w c:\windows\winsxs\x86_wpf-xamlviewer_31bf3856ad364e35_6.0.6001.18000_none_560e4c817cece28f\XamlViewer_v0300.exe
+ 2008-01-05 11:22:01 308,760 ----a-w c:\windows\winsxs\x86_wpf-xpsviewerexe_31bf3856ad364e35_6.0.6001.18000_none_c9336c81088f402c\XPSViewer.exe
+ 2008-01-19 07:37:10 351,232 ----a-w c:\windows\winsxs\x86_wsdapi_31bf3856ad364e35_6.0.6001.18000_none_beb38cd34d56a01d\WSDApi.dll
+ 2008-01-19 06:14:59 16,896 ----a-w c:\windows\winsxs\x86_wsdprint.inf_31bf3856ad364e35_6.0.6001.18000_none_154f3e52b146ef82\WSDPrint.sys
+ 2008-01-19 07:37:10 56,320 ----a-w c:\windows\winsxs\x86_wsdprint.inf_31bf3856ad364e35_6.0.6001.18000_none_154f3e52b146ef82\WSDPrPxy.dll
+ 2008-01-19 07:37:10 237,056 ----a-w c:\windows\winsxs\x86_wsdscdrv.inf_31bf3856ad364e35_6.0.6001.18000_none_d03e46f3c9815a07\WSDScDrv.dll
+ 2008-01-19 07:37:10 54,272 ----a-w c:\windows\winsxs\x86_wsdscdrv.inf_31bf3856ad364e35_6.0.6001.18000_none_d03e46f3c9815a07\WSDScPrx.dll
+ 2008-01-05 11:22:14 1,152,040 ----a-w c:\windows\winsxs\x86_wwf-system.workflow.activities_31bf3856ad364e35_6.0.6001.18000_none_3265f2e277fead59\System.Workflow.Activities.dll
+ 2008-01-05 11:22:15 1,635,376 ----a-w c:\windows\winsxs\x86_wwf-system.workflow.componentmodel_31bf3856ad364e35_6.0.6001.18000_none_8be419790e15a8ca\System.Workflow.ComponentModel.dll
+ 2008-01-05 11:22:15 578,592 ----a-w c:\windows\winsxs\x86_wwf-system.workflow.runtime_31bf3856ad364e35_6.0.6001.18000_none_651add99a006f9de\System.Workflow.Runtime.dll
+ 2008-01-19 05:49:39 521,216 ----a-w c:\windows\winsxs\x86_xnacc.inf_31bf3856ad364e35_6.0.6001.18000_none_b3ab89be7386e838\xnacc.sys
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-09 845360]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-21 266497]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-23 185872]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-07-13 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-13 8433664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-13 81920]
"MSConfig"="c:\windows\system32\msconfig.exe" [2008-01-19 227840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2007-02-21 03:18 366400 c:\program files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DD87B39D-448B-4537-84CA-74114A2568F7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{1A1A3747-B23E-459B-AFDA-FD32BE7C36B1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FB241AA7-3D12-4A94-A58A-AA20C32AE7E0}"= UDP:c:\program files\Everest Poker\CStart.exe:Everest Poker
"{916F2DCF-F451-4BB9-9916-47B8A6C959C2}"= TCP:c:\program files\Everest Poker\CStart.exe:Everest Poker
"TCP Query User{10536944-8DC4-4DE9-B3F5-29A39D78163D}c:\\program files\\participatory culture foundation\\miro\\xulrunner\\python\\miro_downloader.exe"= UDP:c:\program files\participatory culture foundation\miro\xulrunner\python\miro_downloader.exe:Miro_Downloader
"UDP Query User{AE2B598B-09FF-455F-851F-35BE86799CBB}c:\\program files\\participatory culture foundation\\miro\\xulrunner\\python\\miro_downloader.exe"= TCP:c:\program files\participatory culture foundation\miro\xulrunner\python\miro_downloader.exe:Miro_Downloader
"TCP Query User{2753CFD9-E80F-4929-92C0-99D83EEB2722}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Packard Bell - Skype
"UDP Query User{197A4C93-369C-4491-A6BF-B5B8D03213C6}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Packard Bell - Skype
"{40804A6D-5D5E-40FB-830B-B7878BAE7782}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{5D296462-1046-44ED-B29F-34B6018C2A13}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{9C6AC24E-BB05-49B8-9266-FE9E3814CDC1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{67879D93-ACAD-4C42-BB09-EC270D9F6EBD}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{73743937-3D52-45A0-BB5E-C386F807811A}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{14042047-D97A-4A72-A53E-F86DBFAAACD8}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{CF7C7AB4-107D-4BD9-8044-DD0D70B31FBB}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{BD4462B6-D4CD-4B2E-8EC9-8599AB351902}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{3F13A3A7-8975-4DD5-BF7D-D0B299B52AC0}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{8D9CA7A5-AD67-41B6-8D98-E13067659789}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{222CA3E8-2E1F-4B85-879D-1CE9A7F39C99}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"{6F8BCB20-FA9C-4F3F-B378-A51E91341216}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{3CF398C6-C263-436D-9164-99A4FD07C8C8}"= UDP:c:\users\remi\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{C4ED84C6-4A14-4A62-969B-A89E08DD371B}"= TCP:c:\users\remi\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
R3 vm331avs;Bison Webcam;c:\windows\System32\drivers\vm331avs.sys [2007-01-01 943016]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\RTL8187B.sys [2008-06-04 288256]
S4 Ssofsovml;Ssofsovml; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17ecb9a5-3d04-11dd-8629-00140b396c9e}]
\shell\AutoRun\command - l2f.cmd
\shell\explore\Command - l2f.cmd
\shell\open\Command - l2f.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{763e2fac-b40e-11dc-8463-0015af4b68d7}]
\shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{922b4aee-d6f7-11dc-87de-0015af4b68d7}]
\shell\AutoRun\command - F:\h.cmd
\shell\explore\Command - F:\h.cmd
\shell\open\Command - F:\h.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9c11bd96-12d6-11dd-8b5c-0015af4b68d7}]
\shell\AutoRun\command - F:\xn1i9x.com
\shell\explore\Command - F:\xn1i9x.com
\shell\open\Command - F:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9c11bd99-12d6-11dd-8b5c-0015af4b68d7}]
\shell\AutoRun\command - xn1i9x.com
\shell\explore\Command - xn1i9x.com
\shell\open\Command - xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a98fe621-7fe1-11dd-859d-0015af4b68d7}]
\shell\Auto\command - cmd /C launch.bat
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d0dd2b45-ada4-11dd-a3ac-0015af4b68d7}]
\shell\AutoRun\command - G:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f16518d0-054d-11dd-9f0f-0015af4b68d7}]
\shell\AutoRun\command - v.cmd
\shell\explore\Command - v.cmd
\shell\open\Command - v.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa5fc1e6-d947-11dc-849a-0015af4b68d7}]
\shell\Auto\command - fun.xls.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
.
Contenu du dossier 'Tâches planifiées'
2009-01-20 c:\windows\Tasks\Extension de garantie.job
- c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2006-11-21 18:38]
2009-01-20 c:\windows\Tasks\Recovery DVD Creator.job
- c:\program files\Packard Bell\SetupMyPc\MCDCheck.exe [2006-11-21 18:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
MSConfigStartUp-RoxWatchTray - c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=8&key=IESTART
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: www.bitdefender.fr
Trusted Zone: www.secuser.com
Trusted Zone: housecall65.trendmicro.com
FF - ProfilePath - c:\users\remi\AppData\Roaming\Mozilla\Firefox\Profiles\taul91wp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://fr.mg40.mail.yahoo.com/dc/launch?rand=1793606149
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 14:49:30
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
Heure de fin: 2009-01-20 14:50:45
ComboFix-quarantined-files.txt 2009-01-20 12:50:42
ComboFix2.txt 2008-04-15 16:07:06
Avant-CF: 46,116,663,296 octets libres
Après-CF: 46,085,120,000 octets libres
9286 --- E O F --- 2008-12-25 14:42:41